cbcvebase.

Microsoft Windows Server 2012 vulnerabilities

4,005 known vulnerabilities affecting microsoft/windows_server_2012.

Total CVEs
4,005
CISA KEV
150
actively exploited
Public exploits
332
Exploited in wild
207
Severity breakdown
CRITICAL178HIGH2668MEDIUM1104LOW55

Vulnerabilities

Page 24 of 201
CVE-2016-0101P2HIGHCVSS 8.8vr22016-03-09
CVE-2016-0101 [HIGH] CWE-20 CVE-2016-0101: Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, W Microsoft Windows Server 2008 R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow remote attackers to execute arbitrary code via crafted media content, aka "Windows Media Parsing Remote Code Execution Vulnerability."
nvd
CVE-2014-0263P2CRITICALCVSS 9.3vr22014-02-12
CVE-2014-0263 [CRITICAL] CWE-119 CVE-2014-0263: The Direct2D implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windo The Direct2D implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a large 2D geometric figure that is encountered with Internet Explorer, aka "Microsoft Graphics Component Memory Corruption Vuln
nvd
CVE-2025-33064P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < 6.2.9200.255222025-06-10
CVE-2025-33064 [HIGH] CWE-122 CVE-2025-33064: Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.
nvd
CVE-2021-36947P2HIGHCVSS 8.8vr2≥ 6.2.0, < 6.2.9200.234352021-08-12
CVE-2021-36947 [HIGH] CVE-2021-36947: Windows Print Spooler Remote Code Execution Vulnerability Windows Print Spooler Remote Code Execution Vulnerability
nvd
CVE-2026-56647P2HIGHCVSS 8.8vr22026-07-14
CVE-2026-56647 [HIGH] CWE-190 CVE-2026-56647: Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized Integer overflow or wraparound in Windows Remote Access Service Infrastructure allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2026-50666P2HIGHCVSS 8.8vr22026-07-14
CVE-2026-50666 [HIGH] CWE-416 CVE-2026-50666: Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges over a network.
nvd
CVE-2019-0722P2HIGHCVSS 8.8vr2≥ 6.2.9200.0, < publication2019-06-12
CVE-2019-0722 [HIGH] CWE-20 CVE-2019-0722: A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability, an attacker could run a specially crafted application on a guest operating system that could cause the Hyper-V host operating system to execute arbitrary
nvd
CVE-2018-8349P3HIGHCVSS 8.8vr2v(Server Core installation)2018-08-15
CVE-2018-8349 [HIGH] CWE-502 CVE-2018-8349: A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properl A remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "Microsoft COM for Windows Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 20
nvd
CVE-2019-1468P3HIGHCVSS 8.8vr22019-12-10
CVE-2019-1468 [HIGH] CWE-787 CVE-2019-1468: A remote code execution vulnerability exists when the Windows font library improperly handles specia A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka 'Win32k Graphics Remote Code Execution Vulnerability'.
nvd
CVE-2022-21894MEDIUMCVSS 4.4ExploitedPoC≥ 6.2.9200.0, < 6.2.9200.235842022-01-11
CVE-2022-21894 [MEDIUM] Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability Secure Boot Security Feature Bypass Vulnerability
cvelistv5
CVE-2023-32015P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-32015 [CRITICAL] CWE-20 CVE-2023-32015: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-28250P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.242162023-04-11
CVE-2023-28250 [CRITICAL] CWE-191 CVE-2023-28250: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-29363P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-29363 [CRITICAL] CWE-122 CVE-2023-29363: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-32014P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243142023-06-14
CVE-2023-32014 [CRITICAL] CWE-191 CVE-2023-32014: Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
nvd
CVE-2023-35365P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35365 [CRITICAL] CWE-20 CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35366P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35366 [CRITICAL] CWE-20 CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2023-35367P2CRITICALCVSS 9.8vr2≥ 6.2.9200.0, < 6.2.9200.243742023-07-11
CVE-2023-35367 [CRITICAL] CWE-20 CVE-2023-35367: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
nvd
CVE-2018-8494P3HIGHCVSS 8.8vr2v(Server Core installation)2018-10-10
CVE-2018-8494 [HIGH] CWE-611 CVE-2018-8494: A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser proce A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Win
nvd
CVE-2020-0883P2HIGHCVSS 8.8vr22020-03-12
CVE-2020-0883 [HIGH] CVE-2020-0883: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface ( A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0881.
nvd
CVE-2017-0214P3HIGHCVSS 7.0PoCvr22017-05-12
CVE-2017-0214 [HIGH] CVE-2017-0214: Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an elevation privilege vulnerability when Windows fails to properly validate input before loading type libraries, aka "Windows COM Elevation of Privilege V
nvd
Microsoft Windows Server 2012 vulnerabilities | cvebase